Actively exploitedCVSS 7.8 · HIGH
CVE-2026-41091
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
View on NVDAnalysis
Microsoft Defender contains a vulnerability in link resolution that allows a local user to elevate their privileges. While high severity, this is a standard local privilege escalation bug that is typically handled by automated OS updates and does not represent a systemic risk to developer infrastructure.
Relevant roles
WindowsCyberSecurity
Severity
Score: 7.8(HIGH)
Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-59CISA KEV
Added to KEV: 2026-05-20
Federal patch deadline: 2026-06-03
Known ransomware use: Unknown
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS
Probability of exploitation (next 30 days): 0.0655 (6.6%)
Percentile: 91.2%
EPSS: 2026-05-22
Affects
microsoft:malware_protection_engineTechnical description
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Published: 5/20/2026, 1:16:29 PM
Last modified: 5/20/2026, 7:06:36 PM